Back to Newsroom
Threat Intel

North Korea-Linked Hackers Are Hiding Malware Commands Inside Ethereum Transfers

A malware campaign tied to North Korean operators is using ordinary-looking Ethereum wallet transfers to smuggle command-and-control instructions past network defenses — with fallback chains that keep it online.

North Korea-Linked Hackers Are Hiding Malware Commands Inside Ethereum Transfers

What happened

Researchers tracking blockchain-abused malware have documented a campaign, active since June 2025, that uses the Ethereum network itself as a covert signaling channel. Rather than stuffing malicious code into blockchain data — a technique defenders have gotten better at spotting — the operators encode a command server's IP address and port directly inside the recipient address field of routine-looking wallet-to-wallet transfers. Over a 90-day window, researchers counted more than 2,655 of these transactions.

Infected machines periodically query public Ethereum nodes for recent blocks, watch for transfers sent from a specific signing wallet, and decode the destination address back into a real IP and port. No suspicious amount, contract call, or embedded script is needed — just a lookup that looks like normal blockchain traffic to anyone monitoring the wire.

Why it matters

The design gives the malware unusual resilience. Because Ethereum is public, permissionless, and effectively impossible to take down, blocking or seizing one command server does not sever the connection — the infected host can simply read a freshly published address straight off the chain and reconnect. The operators have also built in redundancy across other chains, referencing BNB Smart Chain, Tron, and Aptos wallets as parallel or fallback paths, so a single blocked lookup route doesn't shut the whole operation down.

Infection reportedly starts with a familiar lure: developers are drawn into a fake recruitment process or a trojanized coding project, and a poisoned package or repository delivers a JavaScript-based loader. From there, the malware installs a remote access tool capable of running commands, logging keystrokes, and monitoring the clipboard, alongside a separate one-time credential stealer that targets browser data, password managers, cloud storage sessions, and roughly 133 different cryptocurrency wallet formats. Stolen data reportedly leaves the victim machine through a messaging-bot interface.

What to do

  • Flag unexpected outbound queries to public Ethereum (or BNB Smart Chain/Tron) RPC endpoints from developer workstations, build servers, and CI/CD environments — this traffic pattern is unusual for most business applications.
  • Review any recently added dependencies, npm packages, or cloned repositories on developer machines, especially anything tied to a coding challenge, job interview, or freelance recruitment offer received outside normal hiring channels.
  • Inspect Node.js processes for unexpected outbound connections or evaluated/loaded code that wasn't part of the original project.
  • Don't treat blocking a known IP as remediation — because the malware can pull a new destination straight from the blockchain, a full response needs to remove the loader, the RAT, and any stealer components, not just the network indicator.
  • Rotate credentials and cryptocurrency wallet keys on any machine suspected of infection, given the campaign's focus on wallet and credential theft.
SHARE